What is Detectify?
Detectify Labs
A security research blog
App Security
Writeups
How to
Crowdsource
Bypassing and exploiting Bucket Upload Policies and Signed URLs
AWS
bug bounty
Frans Rosén
Google Cloud
s3 buckets
Most read articles
How I made LastPass give me all your passwords
»
Hacking Slack using postMessage and WebSocket-reconnect to steal your precious token
»
Chrome Extensions – AKA Total Absence of Privacy
»
The danger of recycled phone numbers
2fa
phone number
Get research and tips from Detectify security experts and the Crowdsource hacker community
Subscribe to the Detectify Monthly Round-up
Scratching the surface of host headers in Safari
host headers
password managers
Safari
XSS
GraphQL abuse: Bypass account level permissions through parameter smuggling
Detectify Crowdsource
Changing the URL of social media sharing buttons
open redirect
phishing
social media
Using Google Analytics for data extraction
CSP
Detectify Crowdsource
Google Analytics
How I exploited ACME TLS-SNI-01 issuing Let’s Encrypt SSL-certs for any domain using shared hosting
Security Questions are not secure
Amazon
PayPal
Public Information
Security Questions
Guest Blog: Don’t Leave your Grid Wide Open
Detectify Crowdsource
Peter Jaric
Selenium Grid
TrackMania – a Chrome plugin to stalk your friends on Tinder
Chrome
privacy
Tinder
« Previous
1
…
3
4
5
6
7
…
11
Next »
Start securing your web apps with tech powered by Detectify Crowdsource hackers
Start a 2-week free trial of Detectify and go hack yourself